executive-dashboard-generator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process data from external, potentially untrusted sources such as CSVs, Excel files, Google Sheets, and API responses.
  • Ingestion points: External data sources are identified in references/analysis-coverage.md as the primary input for the dashboard generation workflow.
  • Boundary markers: The skill does not explicitly define delimiters or specific instructions for the agent to ignore or isolate natural language instructions that might be embedded within the provided data.
  • Capability inventory: The skill relies on the agent's standard environment for processing; no high-risk capabilities like arbitrary shell execution or custom network scripts are defined in the provided files.
  • Sanitization: There are no instructions for sanitizing or filtering input data before it is incorporated into the final report output.
  • [SAFE]: The skill follows a clear, instructional workflow for business data analysis. No indicators of prompt injection, obfuscated content, persistence mechanisms, or unauthorized credential access were found in the skill body or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:02 PM
Security Audit — agent-trust-hub — executive-dashboard-generator